Health Information Management

Tip: Train staff on these key HIPAA security points now

HIPAA Weekly Advisor, August 1, 2003

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Organizations have until 2005 to comply with the security rule's training requirement, but you must address some important issues now.

The privacy rule requires organizations to safeguard patient information, and the security rule outlines how to appropriately do so, says William Miaoulis, CISA, principal at Phoenix Health Systems, in Montgomery Village, MD. And the privacy rule's April 14 compliance date has passed. "But protecting PHI is good business practice, not just for the regulations," he says.

Miaoulis lists the following six points to communicate to staff now:

1. Select secure passwords
In many cases, staff members make up their own passwords. Having them do so will not only help employees remember their passwords, it will also eliminate the chances that a system administrator could use an employee's account to access information, says Miaoulis.

"The fallacy is that people don't select good passwords," he says. "We typically only tell [staff] how not to select passwords." But not only do you need to train them to make sure passwords are kept confidential, you also need to train them on how to choose a good password, he says.

"No password is perfect, but there are techniques that staff can use to help them have better passwords," says Miaoulis. He offers the following two methods for creating secure passwords:

  • Use a phrase
    "Remember a phrase and use the first letter of each word," says Miaoulis. "And you should always add a special character and a number. Now, you will have a password that will not show up in a dictionary, which a lot of password-cracking programs use."

    An example would be using the phrase, "I grew up at 522 Main Street," to come up with the password, "IGU@522MS." "It's going to be pretty tough for someone else to guess that," says Miaoulis. A lot of people also use verses from their favorite song or titles of their favorite books, he says.

  • Combine words
    Another method for creating passwords is to combine pieces of a few words, says Miaoulis. As with the phrase method, it is then important to add a special character and a number. "Happy New Year" could become "hapneye#3," he says.

    Go to http://www.himinfo.com/news/tip/ for more tips.



  • Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

    • Briefings on APCs

      Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

    • Medical Records Briefing

      Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

    • Briefings on Coding Compliance Strategies

      Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

    • Briefings on HIPAA

      How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

    • APCs Weekly Monitor

      This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

    Most Popular

    Related Articles